A Chief Information Security Officer (CISO) is evaluating two mutually exclusive risk response proposals for an enterprise cloud platform with an estimated Asset Value () of . Threat intelligence and historical logs establish an baseline Annual Rate of Occurrence () of and an Exposure Factor () of .
- Proposal 1 (Risk Mitigation): Deploy automated microsegmentation and advanced web application defense controls costing annually. This control reduces the to and decreases the to .
- Proposal 2 (Risk Transference): Procure a cybersecurity insurance policy costing annually with a deductible per incident. The policy covers all loss exceeding the deductible per event, effectively capping the Single Loss Expectancy () at , while leaving the at .
Based on quantitative risk analysis, which proposal delivers the maximum net annual financial benefit (gross annual risk reduction minus implementation cost), and what is that net financial benefit value?
- Proposal 2, with a net annual financial benefit of .Answer
- BProposal 1, with a net annual financial benefit of .
- CProposal 1, with a net annual financial benefit of .
- DProposal 2, with a net annual financial benefit of .